Post: 3.70 has new encryption/decryption keys
08-11-2011, 03:03 AM #1
(adsbygoogle = window.adsbygoogle || []).push({}); In not-so-surprising news, the crew over at the other DH -- DemonHades -- dropped insider knowledge on the latest 3.70 firmware. And of course there is more than meets the eye; 3.70 uses new encryption/decryption keys and also patches certain vulnerabilities that Cobra USB took advantage of, making 3.70 more secure than previous firmware

source
You must login or register to view this content.
(adsbygoogle = window.adsbygoogle || []).push({});
08-11-2011, 05:46 PM #20
-O-Z-Z-A-8-8-
At least I can fight
Originally posted by BONExHEAD View Post
"No this won't work. Repackaging the update will change the hash check. So the PS3 would check the update and say "My ass this is official firmware"

Your PS3 would still have to be OFW 3.60+ which would disable all jailbroken features in order for it to output the new Passphrase.

Now doing it with a legit PS3 and the latest update. There is the same hash problem. To grab the passphrase is actually pretty easy. All that needs to be done is as follows and hopefully someone out there can build off the work I have already done so here goes.

Performing a MIM on a PS3 from a computer connected to the same network. This will grab the header that is needed and output in plain text the new passphrase. This can be done on a jailbroken PS3 simply because we can change the file. Now doing this method on a legit PS3 will NOT work. What needs to be done is to create a new CA with openssl to get the ps3 to trust the connection to your computer. Now we cannot simply upload the new certificate we generate to the legit ps3. Now this is where I didn't have time to actually perform the whole setup, but I was thinking what had to be done is pass the new cert in between the connection from PS3. So to get it working it should look like this PS3 (legit), Second computer, 3rd computer.

Have the PS3 send out the request to sign in it then sends header information to your second computer that holds the fake cert and finally your third computer which is setup to arp spoof which will then be a trusted connection from the second computer and unencrypt the headers. The PS3 WILL fail the login this is normal but we are just trying to grab the new passphrase to inject it into charles or whatever tool.

Now this was where I last left off when I was playing around with it so I never got a chance to try it out. And when I get a break from working 6 days a week I will probably try this out but I am hoping someone understands what I am talking about and tries it out. "

Well that sounds like a good idea...^^^ comment from the link in the post


what is a MIM and what program would be usefull in finding the passphrase
08-12-2011, 06:12 AM #21
ƸӜƷ
Banned
what does this mean ???
08-12-2011, 01:28 PM #22
JakeP0500
Do a barrel roll!
Didn't Kakaroto say something like "there is another way" but he wouldn't release till 3.70???
08-12-2011, 01:55 PM #23
Originally posted by 440
what does this mean ???


it means they totally redone the keys again
08-12-2011, 09:14 PM #24
Jakeyy
Expect the unexpected!
Originally posted by Bama205 View Post
i'm not trolling bro,i have the right to my opinion just like everyone else.also gitbrew said its a ''exploit''<------
so a custom ''firmware'' is not a exploit?
im well aware he said this
[ATTACH=CONFIG]10964[/ATTACH]

[ATTACH=CONFIG]10963[/ATTACH]


Yes CFW is a Exploit but Gitbrews new Exploit is not a CFW and they said they will not work on CFW above 3.55, and new news came around 40 mins ago that the new Exploit requires nothing other Internet connection

You must login or register to view this content.

The following user groaned Jakeyy for this awful post:

Bama205
08-12-2011, 09:25 PM #25
Originally posted by jakes2201 View Post
Yes CFW is a Exploit but Gitbrews new Exploit is not a CFW and they said they will not work on CFW above 3.55, and new news came around 40 mins ago that the new Exploitrequires nothing other Internet connection

You must login or register to view this content.
no shit...did you read my post>?
08-12-2011, 09:51 PM #26
Jakeyy
Expect the unexpected!
Originally posted by Bama205 View Post
no shit...did you read my post>?


Yes I did read your and I was telling you because you asked a ****ing question on it you retard
08-12-2011, 10:14 PM #27
Originally posted by jakes2201 View Post
Yes I did read your and I was telling you because you asked a ****ing question on it you retard
i believe i was talking to ''TrueScopes'' and i already knew it was a exploit homo!
08-12-2011, 10:20 PM #28
Originally posted by Bama205 View Post
i believe i was talking to ''TrueScopes'' and i already knew it was a exploit homo!


LOL exploit home

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo